{"apiVersion":"1.0","identifier":"CVE-2026-72103","description":"In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller-s thread keyring via the table device file The refactoring in commit a28d893eb327 (-md: port block device access to file-) accidentally causes the caller-s thread keyring to be kept alive long beyond the caller-s lifetime. As a result, -cryptsetup luksSuspend- silently fails to wipe the LUKS volume key from memory. In detail: -cryptsetup luksOpen- uses its supposedly ephemeral thread keyring to pass the volume key to the kernel. dm-crypt-s crypt_set_keyring_key() copies the key material into its own crypt_config structure and then drops its own reference to the key in the keyring with key_put(). With this fix, restoring pre-v6.9 behavior, the copy in the thread keyring is then promptly garbage collected, such that exactly one copy of the volume key remains. This single copy is correctly wiped from memory on -cryptsetup luksSuspend-. Without this fix, the thread keyring and the volume key in it remains. This second copy is only freed on -luksClose-. -luksSuspend- neither knows about this copy nor has any way to remove it, so the key remains recoverable from RAM after a suspend that is documented to have wiped it. This fix should not introduce new security problems, as the code is anyway gated by CAP_SYS_ADMIN. The device-mapper core, not the calling task, is the legitimate owner of this long-lived file.","publishedAt":"2026-08-15T06:21:24","lastModifiedAt":"2026-08-17T06:18:09","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-72103","cvssScore":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","epssProbability":0.00159,"riskScore":0.74,"affectedProduct":"Linux kernel","affectedVersions":"unknown","vulnerabilityType":"Kernel","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-72103","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-72103","en":"https://www.redsauce.net/en/cves/CVE-2026-72103","fr":"https://www.redsauce.net/fr/cves/CVE-2026-72103","pt":"https://www.redsauce.net/pt/cves/CVE-2026-72103","de":"https://www.redsauce.net/de/cves/CVE-2026-72103","sk":"https://www.redsauce.net/sk/cves/CVE-2026-72103","el":"https://www.redsauce.net/el/cves/CVE-2026-72103"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-72103"}}